Security
JumpServer v4.10.19 LTS
JumpServer v4.10.19 LTS is a maintenance update for the 4.10 Long-Term Support branch, continuing the security hardening, component reliability improvements, and bug fixes delivered throughout the recent 4.10.x releases. The preceding v4.10.18 LTS release improved Chen SQL parsing and memory usage while also addressing security-related issues involving Fastjson and certificate validation.
authentik 2026.8.0
authentik 2026.8.0 is the next major quarterly release following the 2026.5 series. Development includes new identity and lifecycle-management capabilities, OIDC Dynamic Client Registration support, user expiration/offboarding functionality, credential-management improvements, and numerous fixes across authentication, federation, SCIM, WebAuthn, and the administrative interface. The release is still in the release-candidate stage and should not yet be treated as generally available for production deployment.
ManageEngine Password Manager Pro 13236
ManageEngine Password Manager Pro 13.2 Build 13236 is a security-focused maintenance release that addresses multiple critical vulnerabilities, including authenticated remote code execution, broken access control, authorization bypass, and XML External Entity (XXE) issues. Organizations should prioritize upgrading to this build to mitigate the identified security risks.
Vaultwarden 1.37.1
Vaultwarden 1.37.1 is a maintenance release for the self-hosted Bitwarden-compatible server, focused on resolving issues identified after the 1.37.0 release and improving overall service reliability and compatibility.
OpenSSL 4.0.1
OpenSSL 4.0.1 is the first patch release for the 4.0 branch and is a security-focused update. It fixes multiple vulnerabilities affecting PKCS7, CMS, QUIC, OCSP, ASN.1 processing, and cryptographic operations while improving overall library stability and reliability. Organizations using OpenSSL 4.0.0 should upgrade as soon as possible.